CVE-2020-15778
high · 7.4scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
7.4
CVSS
13.0%
EPSS (exploit prob.)
96th
EPSS percentile
2020-07-24
Published
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| openbsd | openssh | < 8.3 |
| openbsd | openssh | 8.3 |
| openbsd | openssh | 8.3 |
| netapp | a700s_firmware | all versions |
| netapp | a700s | all versions |
| netapp | active_iq_unified_manager | >= 9.5 |
| netapp | hci_management_node | all versions |
| netapp | solidfire | all versions |
| netapp | steelstore_cloud_integrated_storage | all versions |
| netapp | hci_compute_node | all versions |
| netapp | hci_storage_node | all versions |
| broadcom | fabric_operating_system | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://access.redhat.com/errata/RHSA-2024:3166
- https://github.com/cpandya2909/CVE-2020-15778/
- https://news.ycombinator.com/item?id=25005567
- https://security.gentoo.org/glsa/202212-06
- https://security.netapp.com/advisory/ntap-20200731-0007/
- https://www.openssh.com/security.html
- https://access.redhat.com/errata/RHSA-2024:3166
- https://github.com/cpandya2909/CVE-2020-15778/
- https://news.ycombinator.com/item?id=25005567
- https://security.gentoo.org/glsa/202212-06
- https://security.netapp.com/advisory/ntap-20200731-0007/
- https://www.openssh.com/security.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-15778